VulnCheck
First CVE: Apr 19, 2023Active for: 3 years
4,980
CVEs Published
More CVEs Published than 96% of tracked CNAs
1245.0
Avg CVEs / Year
More Avg CVEs / Year than 99% of tracked CNAs
7.5
Avg CVSS Score
Higher Avg CVSS Score than 65% of tracked CNAs
0.4%
In CISA KEV
Higher KEV Rate than 83% of tracked CNAs
Trends Over Time
The number and severity of CVEs published by VulnCheck over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 19, 2023
3 years ago
Most Recent CVE
Jul 23, 2026
1 day ago
Top CVEs
All CVEs published by VulnCheck as a CNA, regardless of affected vendor or product.
4,980 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-41940CRITICAL cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the | Apr 29, 2026 | 9.8 | 99 | YES | YES |
CVE-2025-3248CRITICAL Langflow versions prior to 1.3.0 are susceptible to code injection in
the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to e | Apr 7, 2025 | 9.8 | 99 | YES | YES |
CVE-2024-23692CRITICAL Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, unauthenticated attacker to exe | May 31, 2024 | 9.8 | 99 | YES | YES |
CVE-2026-24423CRITICAL SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method. The attacker could point the Sm | Jan 23, 2026 | 9.8 | 98 | YES | YES |
CVE-2026-23760CRITICAL SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous | Jan 22, 2026 | 9.8 | 98 | YES | YES |
CVE-2025-34028CRITICAL The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent install packages that, when expanded by the target server, are vu | Apr 22, 2025 | 10.0 | 98 | YES | YES |
CVE-2024-11680CRITICAL ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP reques | Nov 26, 2024 | 9.8 | 98 | YES | YES |
CVE-2025-34291HIGH Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permissive CORS configuration (allow_ | Dec 5, 2025 | 8.8 | 97 | YES | YES |
CVE-2025-2747CRITICAL An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server component password handling for the server defined None type. A | Mar 24, 2025 | 9.8 | 97 | YES | YES |
CVE-2025-34026HIGH The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative | May 21, 2025 | 7.5 | 96 | YES | YES |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA4,980 CVEs
35%
47%
17%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCriticalUnknown
Attack Vector
Local875 (17.6%)
Network4,035 (81.0%)
Unknown8 (0.2%)
Physical10 (0.2%)
Adjacent Network44 (0.9%)
Attack Complexity
Low4,788 (96.1%)
High184 (3.7%)
Unknown8 (0.2%)
User Interaction
None3,944 (79.2%)
Unknown8 (0.2%)
Required936 (18.8%)
Privileges Required
Low1,803 (36.2%)
High143 (2.9%)
None3,026 (60.8%)
Unknown8 (0.2%)
Exploit Exposure
Signals from CVEs in this cna scope (4980 CVEs).
CISA KEV
19 CVEs
0.4% of CVEs· 83rd percentile
Metasploit
244 CVEs
4.9% of CVEs· 96th percentile
Nuclei
68 CVEs
1.4% of CVEs· 82nd percentile
ExploitDB
13 CVEs
0.3% of CVEs· 74th percentile
Social Chatter
An overview of all social media posts that mention a CVE ID published by VulnCheck as a CNA.
Media Mentions
Media articles that mention a CVE ID published by VulnCheck as a CNA — matched by CVE ID, not by organization name.